This week TechCrunch reported that people using Meta’s Muse agent were failing to finish purchases on Walmart.com. The likely cause is not a ban. It is the little button that asks a visitor to confirm they are human. If that check gets interrupted, it fails, and the agent is booted out of checkout. Walmart is an official Muse partner, and it told TechCrunch the failures were not intentional. The customer on the other end does not care whose fault it is. They just could not buy the thing.
That small mess is the clearest marketing story of the week, and it is hiding inside an announcement most marketers will file under developer news.
On October 6, Meta and Sierra, the customer service AI company co-founded by Bret Taylor and Clay Bavor, announced the Personal Agent Protocol. It is an open standard for how a person’s AI agent identifies itself to a business, signs in, and gets permission to do things. Sierra names Genesys, Instinct, Rocket, Shopify, Stripe and Walmart as partners. Meta’s version of the list also includes NiCE and Decagon. The first draft of the spec, version 0.1, is due later this month.
Here is my read. Whether a customer’s agent gets through your front door is now a decision about customers, not a security setting. And at most companies, nobody in marketing, ecommerce or CX made that decision. A bot filter did.
Agents are already at your door
This is not a future problem. Meta launched Muse, its personal agent, on September 8. Within about a week it was the top free app in Apple’s US App Store, ahead of ChatGPT, according to GeekWire and CNBC. Meta’s David Singleton told CNBC it already has “millions of users in the U.S.” and is “growing rapidly.” That is Meta’s number, not an audited one, but the app chart is public.
What people use it for is ordinary commerce. Singleton listed signing kids up for classes, buying gifts and booking the dentist. GeekWire found early users switching an auto insurance policy, hunting for discount codes at checkout and loading a grocery cart. Muse connects through a public API when a service has one. When it does not, Meta says, the agent “can use the service through a browser the way you would.”
So the agent shows up on your site like a person, clicks like a person, and fills in forms like a person. Except it is not a person, and your website was built over many years to tell the difference.

Some doors close on purpose, most close by accident
Amazon closed its door deliberately. Since September 20, Muse users trying to shop Amazon have seen a popup that says “continued access by an unauthorized AI agent violates Amazon’s Conditions of Use, to which our customers have agreed.” Amazon told GeekWire that Meta gave no notice, that the agent did not identify itself while browsing, and that it appeared to capture customer credentials. Meta says Muse has no visibility into passwords or payment methods. Whatever you think of either side, that is a company making a choice about its customer relationship, with a statement attached.
Most of what TechCrunch’s Sarah Perez found on October 6 looks different. Delta said it has no partnership that lets a third-party agent book on its platforms and is still evaluating. United pointed to its terms of use, which bar “any robot, spider, other automatic device, or manual process” without written permission. Yelp said it does not allow non-human traffic unless the agent pays for its data licensing program. eBay said it restricts unauthorized agents, scraping and model training rather than every agent purchase. Zillow said it allows agents acting for consumers but that its anti-scraping tools can sometimes block them. And Walmart, the partner, is apparently tripping over its own human check.
Read that list as a customer would. Every one of those is a brand experience. Some were chosen by a commercial team. Several sound like they were inherited from an anti-scraping setup nobody has revisited since agents started shopping.
Your CDN may have already picked a side
There is a less visible layer here, and it is worth ten minutes of your week.
On September 15, Cloudflare split its AI bot controls into three separate behaviors: Search, Training and Agent. Agent is defined as “user-directed agents visiting a page on behalf of a human.” That is exactly what Muse is. Cloudflare also migrated existing customers. A domain that had the old “Block AI Bots” switch turned on was moved to Allow for search, Disallow for training, and “Block on pages with ads” for agents. New domains that say they run ads are offered the same agent preset.
Cloudflare’s reasoning is sensible for publishers: an agent loads the page and nobody sees the ad. But think about who turned on “Block AI Bots” last year. My guess is that in a lot of companies it was a security engineer or an agency, reacting to scrapers and training crawlers, with no thought about a shopper’s assistant trying to buy a jacket. TechCrunch reported that some people suspect CDN settings are part of why Muse gets blocked. Cloudflare said it had no specific data to share, so treat that as unproven. What is proven is that your agent policy may have been set for you, by a migration, on a date nobody in marketing marked on a calendar.
My inference, not Cloudflare’s: if you are a retailer running sponsored products or retail media on your own product pages, it is worth asking your web team how “pages with ads” is detected on your site. You do not want your best-selling product page to be the one place an agent cannot reach.
What the protocol actually proposes
The Personal Agent Protocol is an attempt to replace this guesswork with a handshake. Sierra’s post lays out the flow. An agent arrives at your website, discovers what you offer, and starts a session for its user. It can start as a guest, which may be enough to check stock or read a returns policy. When the task needs the customer’s account, the customer signs in on your page or uses credentials already set up with the agent. The customer decides whether the agent gets read-only or write access. Sessions run on OAuth, the same standard behind “sign in with” buttons, and they carry across channels, so a question asked before sign-in and an order change made after count as one visit.
Then the business picks the route. The agent can use your normal website, connect through APIs built on standards like MCP and OpenAPI, or talk to your own customer service agent for tasks that need a conversation. Sierra’s example is a warranty claim.
Meta’s pitch to businesses is blunt: “Turning away a personal agent means turning away the customer behind it.” Meta also says Muse applies what it calls a “one honest person” test, asking whether a reasonable person doing the task by hand would act the same way at the same scale, and that Muse is designed to get explicit user approval before sign-ins, reservations and purchases.
Two caveats matter. First, there is nothing to install yet. The v0.1 spec, design workshops and a reference implementation are all promised for later this month. Finer permissions, push notifications and payments are described as possible future extensions, not features. Second, the coalition is partial. OpenAI and Anthropic are not on board, though Taylor told CNBC he expects them to join. Amazon is not there either. Taylor’s own summary of where things stand is honest: “It is kind of chaos until such a standard exists.”

Why this belongs to marketing
You could read all of this as an IT standards story and wait for the spec. I think that would be a mistake, for three reasons.
The first is that the outcome is a customer experience. When an agent fails at your checkout, the shopper does not see a WAF rule. They see your brand not working. If a competitor’s site lets the agent finish the order, the agent will finish the order there next time. That is a conversion and loyalty problem, and nobody on the security team is measured on it.
The second is that the failure does not disappear. Sierra’s post says it plainly: when a website cannot get the job done, agents “may call the company’s support line or open its web chat.” As CMSWire pointed out, that is a big part of why contact center companies like Genesys and NiCE are in the room. A blocked agent is a cheap web visit turned into an expensive contact center contact, or into a churned customer. Your CX team should hear that from you before they see it in their volume.
The third is measurement, and this is my inference. Agent sessions that your bot tools block are usually filtered out before they reach your analytics. So the demand is real but invisible. You will see a softer conversion rate in some segments and no line in any report that explains it. If your analytics team cannot tell you how many agent sessions you blocked last month, you do not know what this is costing you.
None of that means “let every bot in.” Amazon’s concerns about credentials and undisclosed agents are legitimate, and so are scraping and fraud. It means someone who owns the customer should be deciding where the line sits, on purpose.
What to do this week
Run the test yourself. Have someone on your team use a personal agent to do three real things on your own site: ask a product question, take an item to checkout, and check an order or start a return. Write down exactly where it stops. Do the same on your two closest competitors. This takes an afternoon and will tell you more than any vendor deck.
Pull your bot settings and find their owners. That means the CDN (on Cloudflare, check the Agent setting and whether it changed on September 15), the WAF rules, the human-verification vendor on login and checkout, and any rate limits on account pages. Next to each one, write down who set it, when, and why.
Read your terms of use the way United’s spokesperson did. If your terms ban any automated access, that sentence is now a statement about whether your customers may use the tools they chose. Decide if that is what you mean.
Draft your access tiers before the spec arrives. A simple version: what a guest agent may read (stock, prices, policies, store hours), what a signed-in agent may read (order status, history, loyalty balance), what it may change that can be undone (reschedule a delivery, start a return), and what stays behind an explicit human confirmation (purchases, address and payment changes). Put a named owner from ecommerce or CX on that document, with security as a co-signer, not the other way around.
Brief your contact center. Tell them agent-originated chats and calls are coming, ask whether they can tell them apart today, and agree how to log them.
Ask your vendors three questions in writing. Ask Shopify, Stripe, your CDN and your customer service platform whether they plan to support the Personal Agent Protocol, on what timeline, and at what cost. Then put a reminder on your calendar for the v0.1 release later this month and read it when it lands.
A year ago, blocking bots was simple hygiene. Most of them were scrapers, and none of them had a wallet. That is no longer true. Some of the bots knocking on your site this holiday season are carrying a customer’s shopping list. Decide who gets to answer the door before your firewall does it for you.




